CVE-2025-59509 — Sensitive Info Insertion into Sent Data in Microsoft Windows 10 Version 1809
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 82.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 11
Description
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6